To deploy software with Group Policy, you place a Windows Installer (MSI) package on a network share and add it to the Software installation node of a GPO, and Windows installs it at the next startup or sign-in of every computer or user in scope. The feature is still built into Windows 11 and Windows Server 2025, needs no extra licence, and handles upgrades and removal for you, which makes it a good fit for small and medium domains without Intune or Configuration Manager.
Applies to Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025
Short answer: Copy the MSI to a share where Domain Computers have read access, create a GPO linked to the computers’ OU, go to Computer Configuration » Policies » Software Settings » Software installation, choose New » Package, enter the UNC path to the MSI and select Assigned. Enable “Always wait for the network at computer startup and logon”, then restart a test computer: the application installs before the sign-in screen appears.
Table of Contents
Which method to use
There are several ways to deploy software with Group Policy, plus Intune as the cloud alternative. Software installation is the right default for MSI packages; the others cover EXE installers and remote devices.
| Method | Package | When it installs | Pros | Cons |
|---|---|---|---|---|
| Software installation, assigned to computers | MSI (+ MST) | At startup | Reliable; upgrades and removal built in | MSI only; needs a restart |
| Software installation, assigned to users | MSI | At sign-in or first use | Follows the user | Installs on every PC the user signs in to |
| Software installation, published to users | MSI | When the user chooses it | Self-service from Control Panel | Users must act; rarely used |
| Startup script | EXE or MSI | At startup, as SYSTEM | Works with any installer | You write detection, logging and upgrades |
| GPP immediate scheduled task | EXE or MSI | At the next policy refresh | No restart needed | Same scripting burden as above |
| Intune Win32 or LOB app | .intunewin or MSI | At sync, with retries | Detection rules, reporting, internet delivery | Needs Intune licences and enrolment |
Prerequisites
- An MSI package from the vendor. Many vendors publish an MSI for enterprise deployment; an EXE that merely wraps an MSI can sometimes be extracted, but check the vendor’s documentation before relying on it.
- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.
- A file server (or DFS namespace) reachable from every site during startup.
- Rights to create and link GPOs, and a test OU with at least one computer.
Step 1: Create the distribution share
Computer-assigned packages are installed by the computer account (SYSTEM), so the computer, not the user, needs read access.
New-Item -Path D:\Software -ItemType Directory
New-SmbShare -Name 'Software$' -Path D:\Software -ReadAccess 'Authenticated Users' -FullAccess 'Administrators'
icacls D:\Software /inheritance:r /grant "Administrators:(OI)(CI)F" "SYSTEM:(OI)(CI)F" "Authenticated Users:(OI)(CI)RX"
- Authenticated Users includes computer accounts, so it covers both computer and user deployments. Use Domain Computers instead if users must not browse the share.
- Give only the packaging team write access. Anyone who can replace an MSI on this share can run code as SYSTEM on every computer in scope.
- Use one folder per product and version, for example
\\fs01.contoso.com\Software$\7-Zip\<version>\. Never overwrite an MSI in place; add a new folder for each version. - Prefer a DFS namespace path such as
\\contoso.com\Apps\7-Zip\<version>\, so the file server can be replaced without editing every package.
Step 2: Test the MSI silently
Before you deploy software with Group Policy, prove the package installs silently as SYSTEM. Run it from an elevated prompt on a test PC:
msiexec /i "\\fs01.contoso.com\Software$\7-Zip\<version>\7z-x64.msi" /qn /l*v C:\Temp\7zip-install.log
msiexec /x "\\fs01.contoso.com\Software$\7-Zip\<version>\7z-x64.msi" /qn /l*v C:\Temp\7zip-remove.log
Group Policy installs without a user interface, so any package that needs a dialog, a licence key typed in or a reboot prompt must be handled with properties in a transform (Step 4). Search the verbose log for Return value 3 to find the failing action.
Step 3: Assign the package
This is the core step when you deploy software with Group Policy.
- Create a GPO, for example APP – 7-Zip, and link it to the OU that holds the target computers. One GPO per application keeps upgrades and removals simple.
- Edit the GPO and go to
Computer Configuration » Policies » Software Settings » Software installation. - Right-click Software installation, choose New » Package and browse to the MSI through the UNC path, not a local drive letter. The path is stored in the GPO exactly as you enter it.
- Choose Assigned for a straight install, or Advanced to add a transform or change options before saving.
- Restart a test computer. The package installs during startup, before the sign-in screen appears.
Useful options on the package’s Deployment tab:
- “Uninstall this application when it falls out of the scope of management”: removes the app when the computer leaves the OU or the GPO stops applying.
- “Do not display this package in the Add/Remove Programs control panel”: hides it from the network install list.
- “Install this application at logon”: for user assignment, installs fully at sign-in instead of on first use.
- Advanced » “Make this 32-bit X86 application available to Win64 machines”: needed to deploy a 32-bit MSI to 64-bit Windows.
Assign vs publish
| Option | Target | Behaviour |
|---|---|---|
| Assigned to computers | Computer Configuration | Installs at startup for everyone using the PC. The usual choice. |
| Assigned to users | User Configuration | Shortcuts appear at sign-in; the app installs on first use, or fully at sign-in with “Install this application at logon”. |
| Published to users | User Configuration only | Nothing installs automatically. Users open Control Panel » Programs » Get programs (Install a program from the network) and pick it. |
Step 4: Customise with MST transforms
A transform (.mst) changes MSI properties without editing the vendor’s package: licence keys, install folder, disabled auto-update, components to include. Vendors often supply a tool to create one; otherwise use an MSI editor such as Orca from the Windows SDK.
- Save the MST in the same versioned folder as the MSI.
- When adding the package, choose Advanced, open the Modifications tab, click Add and select the MST through its UNC path.
- Click OK only when the transform list is complete.
Transforms can only be added while the package is being created. To change them later, add the package again as a new package with the new MST, and set it to upgrade the old one.
Step 5: Make startup wait for the network
Software installation runs only in foreground processing, at startup or sign-in, never in the 90-minute background refresh. Windows 11 uses fast logon optimisation by default, so without this step the install often waits for a second or third restart.
- In the same GPO, or a baseline GPO for all workstations, go to
Computer Configuration » Policies » Administrative Templates » System » Logonand enable “Always wait for the network at computer startup and logon”. - If network adapters or Wi-Fi come up slowly, also enable
... » System » Group Policy » "Specify startup policy processing wait time"with 30 to 60 seconds. - Software installation is skipped over a slow link (500 kbps by default). Laptops on VPN may never qualify; use Intune or a script for them.
When a change arrives during a background refresh, the System log shows GroupPolicy event 1112: the Software Installation extension could not apply settings because they must be processed before system startup or user logon. It is informational; the install happens at the next restart.
Step 6: Upgrade or remove a package
Upgrade to a new version
- Copy the new MSI into a new version folder and add it as a new package in the same GPO.
- Open the new package’s properties, go to the Upgrades tab and click Add. Select the old package from the current GPO.
- Choose “Uninstall the existing package, then install the upgrade package” for unrelated or problematic versions, or “Package can upgrade over the existing package” when the vendor’s MSI supports in-place upgrades.
- Tick “Required upgrade for existing packages” so computers that already have the old version upgrade at the next restart.
Keep the old package in the GPO until every computer has upgraded, then remove it with the second option below.
Remove software
Right-click the package, choose All Tasks » Remove and pick:
- “Immediately uninstall the software from users and computers”: uninstalls at the next startup or sign-in.
- “Allow users to continue to use the software, but prevent new installations”: leaves existing installs alone.
Removal only works for installs that this GPO performed. Copies installed by hand or by another tool stay.
EXE installers: the alternatives
You cannot add an EXE to the Software installation node. The ZAP file mechanism only publishes a setup program to users and runs it with the user’s rights, so it is not a real alternative. Instead:
Startup script with detection
Add a PowerShell script under Computer Configuration » Policies » Windows Settings » Scripts (Startup/Shutdown) » Startup. It runs as SYSTEM, so it must check whether the app is already present and log what it does:
$name = 'Example App'
$installed = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*' -ErrorAction SilentlyContinue |
Where-Object DisplayName -like "$name*"
if (-not $installed) {
Start-Process -FilePath '\\fs01.contoso.com\Software$\ExampleApp\setup.exe' -ArgumentList '/S' -Wait
}
The silent switch (/S here) depends on the vendor’s installer. See PowerShell startup scripts with Group Policy for execution policy and logging.
Immediate scheduled task via Group Policy Preferences
Under Computer Configuration » Preferences » Control Panel Settings » Scheduled Tasks, create New » Immediate Task (At least Windows 7), run it as NT AUTHORITY\System and call the same script. It runs at the next policy refresh without a restart. Use item-level targeting or the script’s own detection so it does not reinstall on every refresh.
winget
winget can install from the community repository with winget install --id 7zip.7zip --scope machine --silent --accept-package-agreements --accept-source-agreements. In a SYSTEM startup script it is not on the PATH, and it depends on the App Installer package being present and current, so test carefully and pin the source you trust.
Group Policy vs Intune
| Need | Group Policy Software Installation | Intune |
|---|---|---|
| Package types | MSI only | MSI (LOB) and any installer as Win32 .intunewin |
| Detection | MSI product code | Custom rules: file, registry, MSI code or script |
| Delivery | SMB share at startup, on the LAN | Over the internet, with retries |
| Reporting | Event logs per machine | Central install status |
| Cost | Included with Windows Server | Intune licence |
For hybrid fleets, move one application at a time. Remove it from the GPO with “Allow users to continue to use the software” before assigning the Intune version, so the two tools do not fight. See Intune Win32 app deployment.
Targeting and exceptions
When you deploy software with Group Policy to only part of the estate, control scope at the GPO level:
- Link the GPO to the OUs that should get the app, and use security filtering with a computer group for finer control (remove Authenticated Users from Apply, keep its Read permission).
- A WMI filter can limit a package to a specific architecture or OS build, but keep filters simple; each one is evaluated at every refresh.
- Exclude servers or VDI images with a separate OU rather than exceptions inside the package.
Verify it works
After you deploy software with Group Policy to a pilot OU, check a few machines before widening the link:
- Run
gpresult /h C:\Temp\gp.htmland check the Software Installations section for the package and its deployment state. - In the System log, events from source Application Management Group Policy: 302 (install succeeded), 301 (assignment succeeded), 306 (upgrade succeeded) and 308 (changes applied). Failures show as 101, 102 (install failed) or 108 (failed to apply changes), with an error code.
- In the Application log, MsiInstaller events 11707 (installation completed successfully) and 11708 (installation failed) come from Windows Installer itself.
- Confirm the product from PowerShell without triggering an MSI repair:
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*' |
Where-Object DisplayName -like '7-Zip*' | Select-Object DisplayName, DisplayVersion, InstallDate
Avoid Win32_Product queries for checks; they are slow and make Windows Installer run a consistency check on every installed MSI.
Troubleshooting
Most failures to deploy software with Group Policy come down to timing, share permissions or the package path:
| Symptom | Likely cause | Fix |
|---|---|---|
Nothing installs after gpupdate | Software installation needs startup or sign-in | Restart; look for event 1112 |
| Installs only after two or three restarts | Fast logon optimisation | Enable “Always wait for the network at computer startup and logon” |
| Event 102 with access denied | Computer account cannot read the share or NTFS folder | Grant Authenticated Users or Domain Computers read on both |
| Event 102 with a file not found error | Package added from a local path or moved | Re-add the package through the UNC path |
| Upgrade does nothing | “Required upgrade” not ticked, or old package removed too early | Tick it; keep the old package until upgrades finish |
| Laptops never get the app | Slow link or VPN after sign-in | Use Intune or a scheduled task for remote devices |
| 32-bit MSI missing on 64-bit PCs | Win64 option not enabled | Enable it under Advanced when adding the package |
Roll back or undo
- To remove an application everywhere, use All Tasks » Remove » Immediately uninstall and let computers restart. Do not simply delete or unlink the GPO: without “Uninstall this application when it falls out of the scope of management”, computers keep the software.
- To revert a bad upgrade, add the previous version as a new package that upgrades the faulty one, using “Uninstall the existing package, then install the upgrade package”.
- Keep old version folders on the share until no GPO references them; Windows Installer may need the original MSI for repair and removal.
When you deploy software with Group Policy this way, with versioned folders, one GPO per application and the network-wait setting in place, it stays predictable for years. When you need EXE installers, internet delivery or central reporting, that is the point to move the application to Intune.
Deploy software with Group Policy at a glance

Official documentation: Group Policy Software Installation event IDs (Software Installation Processing), msiexec command reference, Add and assign Win32 apps to Microsoft Intune.
Related guides: Intune Win32 App Deployment: Reliable Packaging and Detection · PowerShell logon/startup scripts with Group Policy · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.
Frequently asked questions
Can I deploy EXE files with Group Policy Software Installation?
No. The Software installation node accepts MSI packages only. For EXE installers, use a startup script or a Group Policy Preferences immediate scheduled task that runs as SYSTEM, or Intune Win32 apps.
What is the difference between assigning and publishing?
Assigned computer packages install at startup for everyone on the PC, and assigned user packages install at sign-in or first use. Published packages are only offered to users in Control Panel, and nothing installs until the user chooses it.
Why does the software not install after gpupdate /force?
Software installation only runs during foreground processing at startup or sign-in. Restart the computer, and enable Always wait for the network at computer startup and logon so the install does not wait for extra restarts.
How do I update an application deployed with Group Policy?
Add the new MSI as a new package, open its Upgrades tab, select the old package and tick Required upgrade for existing packages. Computers upgrade at their next restart.
Does removing the GPO uninstall the software?
Only if the package has Uninstall this application when it falls out of the scope of management enabled. Otherwise use All Tasks, Remove, Immediately uninstall before you remove the GPO.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025
- Last full review
- Next review